BOXX Adds Affirmative AI And Deepfake Coverage To Cyberboxx Business

Estimated reading time: 4 minutes

BOXX Insurance says its small business cyber policy now covers AI and deepfake attacks in plain language. The Toronto-based insurtech, part of Zurich Insurance Group, announced affirmative coverage on July 22 for AI and deepfake events tied to social engineering and security failures. The endorsement sits within Cyberboxx® Business, the firm’s commercial offering.

The move targets a familiar problem. Deepfake-enabled fraud often lands in the seams between cyber and crime policies. We examined that gray zone last month. Affirmative language removes the coverage debate before the claim arrives.

BOXX Insurance deepfake cyber insurance graphic showing a fragmenting digital face beside headline on AI and deepfake coverage, via Cyber Insurance News.

The Threat Behind The Endorsement

BOXX cites Cisco research finding 86% of US business leaders with cybersecurity responsibilities reported at least one AI-related incident in the past year. Treat that number with care. Cisco’s definition of an AI-related incident is broad. It includes employee misuse of AI tools, not just attacks. A KPMG figure for Canada is conditional: 81% of Canadian businesses that experienced fraud also faced an AI-enabled attack. That is 81% of fraud victims, not 81% of all businesses.

The direction of travel is not in dispute. Check Point’s 2026 report documented a surge in AI-powered social engineering and voice impersonation. ClickFix-style attacks jumped roughly 500% last year. European CISOs rank deepfake impersonation among their top fears, with UK leaders most worried.

“Threat actors are exploiting trusted relationships amongst employee and executive networks which can result in handing over credentials or misdirecting payments without an actual breach,” said Erik Tifft, Global Head of Underwriting at BOXX Insurance. That “without an actual breach” line matters. Authorized fraud, where a tricked employee approves the transfer, is exactly where coverage disputes live.

See also  CFC Cyber Development Team Expands U.S. Cyber Insurance Operations

Reinstatement Is The Quiet Headline

BOXX pairs the endorsement with its First Party Each and Every Loss feature. That reinstates the policy’s aggregate limit after each cyber incident. As AI lowers the cost of running scams at scale, the odds of multiple claims in one policy period rise. Full-term limit reinstatement at the SME level is uncommon. For brokers, it may be the more useful selling point.

“Our underwriting is keeping up with the higher frequency and the changing nature of emerging cyber and AI-driven threats,” Tifft continued. He said BOXX is broadening affirmative coverages to capture new forms of cybercrime, “whether they occur via systems breaches or through advanced social engineering.”

The release omits the details brokers will ask about first. No sublimits, no jurisdiction rollout, and no word on whether existing policyholders get the endorsement automatically. We have asked BOXX for specifics.

BOXX has been busy on the product front. The firm launched Tech E&O by BOXX in late 2025, rolled out the Cyberboxx Assist prevention suite, and published broker AI survey data in January. Identity verification, as we explored with HYPR’s CEO, remains the harder problem. Policy language can pay for the loss. It cannot spot the fake voice on the call.

FAQ – Deepfake Cyber Insurance

What did BOXX Insurance announce?

Affirmative coverage for AI and deepfake events within Cyberboxx® Business, covering social engineering and security failures.

What is Each and Every Loss reinstatement?

BOXX restores the policy’s aggregate limit after each cyber incident, keeping full coverage available for the whole policy term.

Does the coverage require a systems breach?

No. BOXX says it responds to losses from advanced social engineering, including payments misdirected without any technical intrusion.

Leave a Comment

×